lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-Id: <200908270717.28632.prb@lava.net>
Date: Thu, 27 Aug 2009 07:17:28 -1000
From: Peter Besenbruch <prb@...a.net>
To: full-disclosure@...ts.grok.org.uk
Subject: Re: [SECURITY] [DSA 1862-1] New Linux 2.6.26
	packages fix privilege escalation

On Thursday 27 August 2009 02:11:10 morla wrote:
> when i
>  $ aptitude update ; aptitude safe-upgrade
> or
>  $ apt-get update ; apt-get upgrade
>
> it tells me that im up 2 date. but in this release the bug is still
> included,.,.
>
>
> i had to install "linux-image-2.6.26-2-686-bigmem" via
>  $ aptitude install linux-image-2.6.26-2-686-bigmem
> by hand.
>
> why is this? and how do i ensure that im not being fooled by aptitude or
> apt?

That depends. Do you include proposed-updates in your sources.list?

-- 
Hawaiian Astronomical Society: http://www.hawastsoc.org
HAS Deepsky Atlas: http://www.hawastsoc.org/deepsky

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ